CVE-2020-20139

MEDIUM

Flexmonster Pivot Table & Charts 2.7.17 - Cross-Site Scripting in Remote JSON Component

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-20139. PoCs published by Marco Nappi.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Flexmonster Pivot Table & Charts 2.7.17 via the 'path' parameter in file_specs.php. The payload uses an SVG onload event to trigger arbitrary JavaScript execution.

Description

Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

Exploits (1)

exploitdb WORKING POC
by Marco Nappi · textwebappsmultiple
https://www.exploit-db.com/exploits/49305

This exploit demonstrates a reflected XSS vulnerability in Flexmonster Pivot Table & Charts 2.7.17 via the 'path' parameter in file_specs.php. The payload uses an SVG onload event to trigger arbitrary JavaScript execution.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Flexmonster Pivot Table & Charts 2.7.17
No auth needed
Prerequisites: User interaction to navigate to a crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0162
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
flexmonster/pivot_table_\&_charts 2.7.17
Published Dec 17, 2020
Tracked Since Feb 18, 2026